scorecard-review

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes data from external sources, specifically Harness IDP entities, scores, and technical documentation. This creates a surface where embedded instructions in those external sources could theoretically influence the agent's behavior. However, the skill's capabilities are limited to information retrieval and report generation, with no access to high-risk tools such as shell execution or file system writes.
  • Ingestion points: Tool outputs from harness_list and harness_get (defined in SKILL.md).
  • Boundary markers: Not explicitly used in the instruction set.
  • Capability inventory: The skill is restricted to reading metadata and lacks capabilities for arbitrary command execution, network exfiltration, or persistence.
  • Sanitization: None explicitly defined; relies on standard tool-calling safety measures.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 11:25 PM
Security Audit — agent-trust-hub — scorecard-review